All Banks and NBFCs (regulated entities)
On July 15, 2026, the Reserve Bank of India (RBI) published a draft framework aimed at strengthening data security and data risk management systems at banks and non-banking financial companies (NBFCs) engaged in digital banking. The guidance addresses the growing reliance on digital channels and fintech partnerships that increase data exposure. Banks and NBFCs would be required to implement enhanced data protection controls. While not an enforcement action, the framework signals increased supervisory expectations for institutions operating in the digital and BaaS-adjacent space in India.
Verified from source: The RBI issued a draft framework on July 15, 2026, proposing that all banks, NBFCs, and RBI-regulated financial institutions build robust data security, data governance, and data risk management systems for digital banking. Comments were invited until August 17, 2026.
- Banks partnering with fintechs in India may face new data security compliance requirements
- Could increase compliance costs for digital banking and BaaS-style arrangements in India
- Signals global regulatory trend toward tighter data governance in fintech-bank partnerships
- NewsIndia TV